SB2020022506 - Multiple vulnerabilities in D-Link DIR-867, DIR-878 and DIR-882 routers
Published: February 25, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Incorrect Implementation of Authentication Algorithm (CVE-ID: CVE-2020-8863)
The vulnerability allows a remote attacker to to bypass authentication process.
The vulnerability exists due to a lack of proper implementation of the authentication algorithm within the handling of HNAP PrivateLogin login requests. A remote attacker on the local network can bypass authentication and reset the admin password.
An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the router.
2) Incorrect Comparison (CVE-ID: CVE-2020-8864)
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a lack of proper handling of empty passwords within the handling of HNAP strncmp login requests. A remote attacker on the local network can bypass authentication and reset the admin password.
An attacker can leverage this vulnerability to execute arbitrary code on the router.
Remediation
Install update from vendor's website.